Status: July 23, 2026

1. Responsible Party

SelectCode GmbH
Oskar-vonMiller-Straße 11
82008 Unterhaching
Germany

Contact:
Email: datenschutz@meingpt.com
Telephone: +49 89 54198646
Website: https://meingpt.com

Management: Florian Baader, Reiner Conrad

Data Protection Officer:
heyData GmbH
Schützenstr. 5
10117 Berlin
Email: datenschutz@heydata.eu

Competent Supervisory Authority:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach

2. Overview of Processing

This privacy policy informs you about the nature, scope and purpose of the processing of personal data when using our B2B AI platform meinGPT.

Important note for corporate customers: As an administrator, you are responsible for ensuring that data is used in accordance with data protection regulations within your organisation, particularly when processing employee data. A data protection impact assessment (DPIA) may be required.

Who is responsible for which data? For content data (your chat inputs, uploads, knowledge vault), your company or organisation — or, if you registered directly yourself, you yourself — is the controller under the GDPR; meinGPT processes this data solely as a processor on the controller's instructions (see the data processing agreement, DPA). The controller determines the legal basis, purposes and storage period of this processing. For account, billing and security data, meinGPT is itself the controller — this notice describes our own processing in that respect.

Types of Data Processed

Data Subjects

The following legal bases concern the processing for which meinGPT is itself the controller (in particular account, billing and security data). For content data, the controller (your company or, on direct signup, you yourself) determines the legal basis; meinGPT processes it as a processor (see Section 4.1 and the DPA):

4. Purposes of Data Processing

4.1 Provision of the Platform (processing of content data)

When you use the platform, meinGPT processes your content data (chat inputs, uploaded files, AI interactions) solely as a processor, on behalf of and on the instructions of the controller — your company or, where you registered directly, yourself.

Controller, legal basis and purposes are determined by the controller; meinGPT does not set them independently. Details are governed by the data processing agreement (DPA, Art. 28 GDPR) and, where applicable, the controller's own privacy notice.

Storage period: the provider's default retention is 12 months after last activity (chats) or after upload (documents); the controller can configure different retention and deletion rules (see Section 10). After the contract ends, the data is deleted in accordance with the DPA.

No use for training: your content is not used to train AI models (see Section 7).

4.2 User Management and Authentication

Processed data:

Purpose:

Legal basis: Art. 6(1)(b) GDPR

Storage period:

4.3 Billing and Payment Processing

Processed data:

Purpose:

Legal basis:

Storage period: 10 years in accordance with § 147 AO and § 257 HGB

4.4 Employee Usage Analyses (B2B)

⚠️ ATTENTION Data protection risk: The processing of employee usage data is highly sensitive in terms of data protection law. Administrators must establish their own legal basis (e.g. works agreement) before activating these functions.

Processed data:

Purpose:

Legal basis:

Storage period:

Data protection guarantees:

5. Recipients and Categories of Recipients

5.1 AI Model Providers

The AI providers used in the standard configuration process your data exclusively within the EU; your content is not used to train the models. If you, as an administrator, actively enable models or services located outside the EU/EEA within the platform, processing may take place outside the EU to that extent (see Section 6); such models are specially marked within the platform. We distinguish two levels of digital sovereignty:

Level 1 – EU-Sovereign — based in the EU with no parent company outside the EU; processing governed solely by European law:

Level 2 – EU Data Residency — processing exclusively in EU data centres; also includes the EU entities of globally operating providers (parent company possibly outside the EU):

The always-current, complete list of our sub-processors is available in our Trust Center and — as a contractually binding annex — in your data processing agreement (DPA).

5.2 Infrastructure Service Provider

Hetzner Online GmbH (hosting, Germany)

Where this infrastructure processes content data, it does so solely as a processor on the controller's instructions (DPA); the legal basis stated above concerns the contractual relationship between you or your company and meinGPT.

5.3 Other Service Providers

For the following processing, in which we act as controller, we engage processors on the basis of agreements pursuant to Art. 28 GDPR (where a third-country element applies, safeguarded via the EU Standard Contractual Clauses or the EU-US Data Privacy Framework):

Payment Processing & Invoicing

Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland; parent company USA)

Hyperline (Hyperline SAS, Paris, France)

Customer-activated integrations (e.g. Google Workspace, Microsoft 365) are to be distinguished from the above: if an administrator activates such an integration, the Customer is itself responsible for the processing there and concludes the necessary agreements with the respective provider independently (see Section 6). Newsletters, webinars and other marketing communication are directed at website visitors and are covered in our website privacy policy.

6. Third Country Transfers

Processing by our AI providers and sub-processors takes place exclusively within the EU — there is therefore no transfer to third countries in this respect.

A third-country element can only arise from integrations you optionally activate (e.g. Microsoft 365). In those cases, any transfer is based on the EU Standard Contractual Clauses or — where applicable — the EU-US Data Privacy Framework; concluding and being responsible for your own agreements with those providers is up to you.

Despite protective measures, there is a residual risk with optional third-country integrations, as the legal situation in third countries may differ from EU standards.

7. No Use for AI Training

Important guarantee: Your data will not be used by us or our processors for training AI models. This is contractually agreed with all providers.

8. Your Rights as a Data Subject

For content data, your company (or, on direct signup, you yourself) is the controller — direct any data-subject requests to them; meinGPT assists the controller in accordance with the DPA. For account, billing and security data, for which meinGPT is the controller, you can exercise the following rights directly against us:

8.1 Right of Access (Art. 15 GDPR)

You can request information about your personal data processed by us.

8.2 Right to Rectification (Art. 16 GDPR)

You can request the rectification of inaccurate data or the completion of incomplete data.

8.3 Right to Erasure (Art. 17 GDPR)

You can request the erasure of your personal data ("right to be forgotten").

8.4 Right to Restriction of Processing (Art. 18 GDPR)

You can request the restriction of the processing of your data.

8.5 Data Portability (Art. 20 GDPR)

You have the right to receive your data in a structured, machine-readable format.

8.6 Right to Object (Art. 21 GDPR)

You may object to the processing of your data.

You may withdraw your consent at any time with effect for the future.

8.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority.

How to exercise your rights:

9. Cookies and Tracking

We only use technically necessary cookies:

Session cookies: To maintain your login

Preference cookies: For your settings (language, theme)

No tracking cookies: We do not use any analysis or marketing cookies.

10. Storage Periods at a Glance

Administrator-Controlled Retention (B2B)

Full control for your organisation: As a B2B platform, we enable your administrators to set retention periods themselves in accordance with your company policies, compliance requirements and business needs.

Available Retention Options

Data TypeAdmin OptionsDefault (if not configured)Notes
Business Data
Chat histories & AI interactions30 days to unlimited12 monthsAdmin selectable by category
Uploaded documents30 days to unlimited12 monthsSeparate setting possible
Workflow data30 days to unlimited12 monthsDependent on business processes
Technical Data
API logs7-90 days30 daysFor debugging & billing
Security logs (IP addresses)7-180 days90 daysObserve compliance requirements
Not Configurable
Invoice data10 years (legal)-§ 147 AO, § 257 HGB
Contract data6 years after end-limitation periods
Account basic dataContract term + 30 days-recovery period

How Admin Control Works

Important for administrators: As an organisation, you are responsible for:

Our shared responsibility model:

Recommendations by Industry

IndustryRecommended Chat RetentionJustification
Financial services5–7 yearsRegulatory requirements (MiFID II, etc.)
Healthcare3–10 yearsPatient documentation, MDR
Public sector2-5 yearsArchiving obligations
Tech/software6-18 monthsProject cycles, support
Consulting2-5 yearsProject documentation

Additional Features

Note: Employees can request the deletion of their personal data at any time, provided that there are no legal retention obligations or legitimate business interests that prevent this.

Technical Implementation of Deletion

11. Data Security

We use extensive technical and organisational measures (TOMs):

Details can be found at: Technical and Organisational Measures

12. Newsletter, Webinars and Marketing Communication

Newsletters, webinar invitations and other marketing communication are directed at website visitors and prospects, not at your use of the platform. The processing of this data — including email delivery via our service provider Resend — is described in our website privacy policy.

13. API Services

Special features for API users:

14. Protection of Minors

Our B2B services are aimed exclusively at companies and their adult employees. Use by persons under the age of 18 is not permitted.

15. Changes to the Privacy Policy

We reserve the right to amend this privacy policy. The current version can always be found on our website. We will inform you by email in the event of significant changes.

16. Contact

If you have any questions about data protection, please contact:

Data Protection Officer:
heyData GmbH
Schützenstr. 5
10117 Berlin
Email: datenschutz@heydata.eu